Menu

Link

Another MongoDB database exposes personal data of 66M users
22 malware infected apps on Play Store found draining phone’s battery
6 Critical Website Elements You Need to Review
415,000 routers infected by cryptomining malware – Prime target MikroTik
New AI tool aims to make CAPTCHA a thing of the past
ThreatList: Gift Card-Themed BEC Holiday Scams Spike
Australia Anti-Encryption Law Triggers Sweeping Backlash
TA505 Crooks are Now Targeting US Retailers with Personalized Campaigns
Using Fuzzing to Mine for Zero-Days
Three years in jail for teenager who spammed out school bomb threats
Microsoft Calls For Facial Recognition Tech Regulation
Infected WordPress Sites Are Attacking Other WordPress Sites
Facebook Defends Data Policies On Heels of Incriminating Internal Docs
Malicious Chrome extension which sloppily spied on academics believed to originate from North Korea
Smashing Security #107: Sextorting the US army, and a Touch ID scam
White House Facial Recognition Pilot Raises Privacy Alarms
Adobe Flash Zero-Day Leveraged Via Office Docs in Campaign
Kubernetes Flaw is a “Huge Deal,” Lays Open Cloud Deployments
Adobe Patches Zero-Day Vulnerability in Flash Player
It looked like a Citrix ShareFile phishing attack, but wasn’t
Google Chrome 71 Touts 43 Fixes, Fights Ad Abuse
Windows 10 version 1809 is incompatible with Morphisec anti-malware
1-800-Flowers Becomes Latest Payment Breach Victim
Google Patches 11 Critical RCE Android Vulnerabilities
Quora Breach Exposes a Wealth of Info on 100M Users
Quora hack leaves details of 100 million accounts exposed
Quora hacked: Personal data of 100 million users stolen
Magecart Group Ups Ante: Now Goes After Admin Credentials
Malware since 2017: Auction giant Sotheby’s Home hit by Magecart attack
Lawsuit Claims Pegasus Spyware Helped Saudis Spy on Khashoggi
Fitness-tracking apps caught misusing Touch ID to steal money from iPhone users
Digitize and automate your customer agreement process for financial transactions. Download this free OneSpan guide.
Private data of more than 82 million US citizens left exposed
Chris Vickery on the Marriott Breach and a Rash of Recent High-Profile Hacks
U.S. Military Members Catfished and Hooked for Thousands of Dollars
Lenovo Ordered to Pay $7.3M in Superfish Fiasco
iOS Fitness Apps Robbing Money From Apple Victims
YouTuber PewDiePie Promoted Via 50K Hacked Printers
Moscow’s cable car service shuts down in 2 days after ransomware attack
Someone hacked 50,000 printers to promote PewDiePie YouTube channel
Indian police & Microsoft busts tech support scam centers
Marriott hotel data breach: Sensitive data of 500 million guests stolen
Dunkin Donuts Perks loyalty data breach: Change your password
Feds charge 2 Iranian hackers behind SamSam ransomware attacks
Gang sentenced for installing card skimmers on gas pumps & stealing data
Dell resets all customer passwords after security breach
FBI & Google shut down largest-ever Ad fraud scheme ‘3VE’
Lenovo to pay $7.3m for installing adware in 750,000 laptops
Podcast: Breaking Down the Magecart Threat (Part Two)
Bing Warns VLC Media Player Site is ‘Suspicious’ in Likely False-Positive Gaff
Newsmaker Interview: Katie Moussouris on Improving Bug Bounty Programs
2014 Marriott Data Breach Exposed, 500M Guests Impacted
Marriott warns of hack. 500 million Starwood hotel guests’ personal data could be exposed.
Critical Zoom Flaw Lets Hackers Hijack Conference Meetings
Cisco Patches Critical Bug in License Management Tool
Hackers Breach Dunkin’ Donuts Accounts in Credential Stuffing Attack
US charges Iranian hackers for SamSam ransomware attacks
Smashing Security #106: Google Maps, Fed phishing, and Grinch bots
Dell Warns of Attempted Breach on Network
Microsoft Warns of Two Apps That Expose Private Keys
ThreatList: Cryptominers Dominate Malware Growth in 2018
FBI Sinkholes $38M Global Ad Fraud Operation
Germany proposes security guidelines for routers, but not everybody is happy
School district fails to reclaim $120,000 wired by bank to scammer
The Nature of Mass Exploitation Campaigns
Pegasus Spyware Targets Investigative Journalists in Mexico
Cisco Re-Issues Patch For High-Severity WebEx Flaw
Cheetah Mobile Blames SDKs for Rampant Ad Fraud in Its Android Apps
Widespread Malvertising Campaign Hijacks 300 Million Sessions
More details on One Planet York app vulnerability doesn’t paint council in a good light
When the FBI rather than the fraudsters make the fake FedEx website
Did UK city council over-react to a vulnerability report in its recycling app or not?
Knuddels Flirt App Slapped with Hefty Fine After Data Breach
Mobile Rotexy Malware Touts Ransomware, Banking Trojan Functions
USPS, Amazon Data Leaks Showcase API Weaknesses
User Confidence in Smartphone Security Abysmal
Bug Bounty: Earn $40,000 for hacking Facebook, Instagram or WhatsApp
Man arrested for stealing $1m from Silicon Valley Exec via SIM-swapping
L0rdix malware on dark web steals data, mines crypto & enslaves PCs as botnet
Adult video game website High Tail Hall hacked; user data stolen
Hacker takeovers Drake’s Fortnite account to yell racial slurs
Spotify Phishers Hijack Music Fans’ Accounts
Threatpost News Wrap Podcast for Nov. 23
Old Printer Vulnerabilities Die Hard
ThreatList: One-Third of Firms Say Their Container Security Lags
SIM swap! Man charged after million dollar cryptocurrency theft
Zero-Trust Frameworks: Securing the Digital Transformation
Podcast: Breaking Down the Magecart Threat (Part One)
As Black Friday Looms, IoT Gadgets Take the Risk Spotlight
Smashing Security #105: Facebook, Nietzsche, Tesla, and Nicole
Podcast: Why ‘Throwing Money’ at Threats Won’t Work
FCC Addresses Robocalling – But Questions Remain
Emotet’s Thanksgiving Campaign Delivers New Recipes for Compromise
Amazon warns customers it leaked their names and email addresses
High Tail Hall data breach exposes over 400,000 furry fans
Hackers target critical WordPress plugin flaw to install backdoors and create admin accounts
Sofacy APT Takes Aim with Novel ‘Cannon’ Trojan
Critical Adobe Flash Bug Impacts Windows, macOS, Linux and Chrome OS
Gmail Glitch Enables Anonymous Messages in Phishing Attacks
APT29 Re-Emerges After 2 Years with Widespread Espionage Campaign